Files
acdl/adapters
Jon Chery 361fe600a9 feat(P61): L2 lifecycle pipeline — extend matrix + workflows + tests
Extend the modules-lifecycle pipeline with L2 composition modules
(static-assets, microservice) per REQ-128:

- pipelines/modules-lifecycle.yml: added l2-lifecycle-apply/modify/destroy
  stages + l2_modules matrix entry
- .gitea/workflows/modules-lifecycle.yml + .github/workflows/modules-lifecycle.yml:
  added l2-lifecycle job (byte-identical), matrix over [static-assets,
  microservice], needs ci-vpc-apply, has apply/modify/destroy steps.
  ci-vpc-destroy now needs both [lifecycle, l2-lifecycle].
- schemas/modules-lifecycle-pipeline.schema.json: added l2_modules to matrix
- scripts/run_l2_lifecycle_test.sh + run_l2_lifecycle_destroy.sh: L2 wrappers
  that set ACDL_REMOTE_STATE_KEY=spike/ci-vpc/terraform.tfstate so the
  microservice composition's terraform_remote_state reads from the CI VPC
- adapters/terraform/adapter.py: parameterized remote_state key via
  ACDL_REMOTE_STATE_KEY env var (default: platform/terraform.tfstate)
- modules/l2/static-assets/examples/complex.yml: fixed bucket_name to match
  simple (my-static-site) so terraform modifies in-place (adds CDN + WAF)
- modules/l2/microservice/examples/complex.yml: fixed bucket_name to match
  simple (my-microservice-demo), added desired_count:2 (modify variant)
- tests/test_pipeline_contract.py: 7 new L2 tests (l2 job exists, matrix
  lists both modules, apply/modify/destroy steps, needs ci-vpc-apply,
  ci-vpc-destroy needs both, contract matrix lists l2_modules)
- pipelines/README.md: updated stages for L2

Regression: 485 passed, 5 deselected. Gitea + GitHub workflows byte-identical.

---ci---
project: acdl
phase: P61
milestone: v1.11
status: execute
---/ci---
2026-07-28 20:17:27 +00:00
..

ACDL Adapters

Overview

Adapters translate the engine-agnostic Target Stack IR to engine-specific formats. The Terraform adapter is the primary adapter (IR → HCL). Policy adapters translate security tool output into normalized PolicyCheckResult records that the confidence signal consumes in an engine-agnostic way.

Existing Adapters

Adapter Path Input Output Purpose
Terraform adapter adapters/terraform/adapter.py Stack instance JSON Terraform HCL (main.tf, terraform.tf, providers.tf) Compiles IR to Terraform
Checkov adapter adapters/terraform/policy/checkov_adapter.py Checkov JSON PolicyCheckResult records Translates Checkov results
Wiz adapter adapters/wiz/wiz_adapter.py Wiz API issues JSON PolicyCheckResult records Translates Wiz security findings
Kyverno adapter adapters/kyverno/kyverno_adapter.py Kyverno PolicyReport JSON PolicyCheckResult records K8s-native policy translation

How to Write an Adapter

Terraform Adapter Extension

  1. Add a stack type → Terraform type mapping to TYPE_MAP.
  2. Add non-identity input mappings to INPUT_MAP.
  3. Add non-identity output mappings to OUTPUT_MAP.
  4. Add a specialized _emit_resource branch if the resource needs nested blocks (e.g. inline policies, rule sets).

Policy Adapter Pattern

  1. Define SEVERITY_MAP and RESULT_MAP dicts that translate the engine's native severity/result vocabulary to the PolicyCheckResult enums.
  2. Implement _to_pcr(raw_record, contract_id)PolicyCheckResult dict.
  3. Implement adapt(input_path, contract_id) → list of PolicyCheckResult dicts.
  4. Implement is_configured() → bool (env var check) so the platform can skip the adapter when credentials are absent.

How to Wire an Adapter

  • Terraform adapter — invoked by scripts/run_platform.sh Step 3 (terraform-plan).
  • Checkov adapter — invoked by scripts/run_platform.sh Step 5 (checkov).
  • Wiz / Kyverno adapters — optional Steps 5b/5c, run only when the relevant env vars are set.
  • All policy adapters output records that are validated against schemas/policy_check_result.schema.json.

Dependencies

  • jsonschema, pyyaml — used by all adapters for loading and validating inputs.
  • boto3 — used by the Wiz adapter for AWS API access.
  • checkov — used by the Checkov adapter to run policy scans.
  • No external deps for the Terraform adapter (pure Python).

How to Test Adapters

  • tests/test_adapter.py — Terraform adapter (TYPE_MAP, resource emission, refs, outputs).
  • tests/test_checkov_adapter.py — Checkov adapter.
  • tests/test_wiz_adapter.py — Wiz adapter.
  • tests/test_kyverno_adapter.py — Kyverno adapter.
  • All adapter tests load fixtures from tests/fixtures/ and use moto for AWS mocking.

Where to Write Tests

  • tests/test_<adapter_name>.py paired with tests/fixtures/<adapter>_fixture.json.

Adding a New Adapter

  1. Create adapters/<name>/<name>_adapter.py.
  2. Implement adapt() and (for policy adapters) is_configured().
  3. Add the adapter's engine name to the engine enum in schemas/policy_check_result.schema.json if it is a policy adapter.
  4. Write a test (tests/test_<name>_adapter.py) plus a fixture (tests/fixtures/<name>_fixture.json).
  5. Add it to scripts/run_platform.sh if it is invoked at runtime.
  6. Update this README.